Exposed Task Object in Kestra Orchestration Platform by Kestra
CVE-2026-73246

7.5HIGH

Key Information:

Vendor

Kestra-io

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-73246?

The Kestra orchestration platform, prior to version 2.0.0-rc6, contains a vulnerability where the WorkerEndpoint exposes a GET endpoint without authentication. This flaw allows unauthorized access to the live Task object, inadvertently revealing sensitive information such as command details, environment variables, HTTP headers, connection specifications, plaintext credentials, and execution identifiers. Despite the protection on the main API monitoring port 8080, the lack of secure access to this endpoint could lead to significant security risks for users.

Affected Version(s)

kestra < 1.3.31

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.